User Stories & Bugs (ADO) (click a row for details)
Pipeline Quality (CI)
⚠️ flags below an 85% pass rate; the m5 score band needs 95%+ - a repo can show ✅ 0 (not flagged) and still have score headroom. Hover a badge for the exact pass rate.
SonarQube Analysis
Severity mapping: Blocker=Critical, Critical=High, Major=Medium, Minor+Info=Low. Locked to each repo's default branch.
Snyk Analysis
Locked to each repo's default branch (Snyk monitors multiple branches as separate projects). Counts are independently computed and may not exactly match Snyk's own dashboard.
Security Posture
Portfolio-wide rollup of SonarQube + Snyk findings - Scope, Coverage, Remediation, and Compliance Deviations are computed across every scanned repo, not tied to one card above.
Automation Maturity
Portfolio-wide automation KPIs, computed from ADO work-item evidence plus CI pipeline test/quality/security gate detection.
Technical Stack & Reusability
Starter-grade: a dependency-manifest scan (package.json / pubspec.yaml / *.csproj) checked against a small curated reference list - not a live vulnerability/deprecation feed. See each KPI's forecast note for exact evidence used.
Data Gap Alerts (instrumentation problems, not work items)
Governance Gap (portfolio-wide, not app-specific)
KPIs with no AssessmentCriteria rubric file - no tool can ever score them until one exists.
Pick an app and click Scan Now to check for items that could drop your PEMM score.
Scanning…